A tailored course, built for your situation
Direct handoff of SLSA framework decisions from senior security leads
Become the named owner of critical supply chain security outcomes with documented authority
Who this is for
Senior technical practitioner influencing security framework adoption without formal mandate
Who this is not for
Junior admins learning Jira basics, product marketers, or executives seeking board-level summaries
What you walk away with
- Own SLSA implementation decisions with peer-recognized authority
- Deliver audit-ready packages for third-party reviewers without rework
- Produce version-controlled SLSA implementation playbooks used across teams
- Receive direct escalations from security architects on SLSA gap remediation
- Build cross-functional influence by resolving SLSA integration blockers
The 12 modules (with all 144 chapters)
- What SLSA solves in practice
- Key components: Attestations, Provenance, Transparency
- SLSA vs SBOM: distinct roles
- Mapping SLSA to build integrity
- Common anti-patterns in rollout
- Role of artifact signing
- Integration with public registries
- Verifiable build pipelines
- Chain of custody design
- SLSA and regulatory alignment
- Toolchain gaps in Level 2
- Common ownership models
- Source repository controls
- Branch protection standards
- Pull request enforcement
- Build trigger validation
- Human vs automated merges
- Version tagging policy
- Artifact naming conventions
- Log retention for audit
- Initial provenance metadata
- SLSA Level 1 checklist
- Cross-team signoff workflow
- Documentation for reviewers
- Dedicated build environments
- Immutable build outputs
- Reproducible builds overview
- Build platform isolation
- Service account governance
- Signed provenance generation
- Provenance schema structure
- Linking builds to issues
- Automated policy checks
- Provenance attestation format
- Time window validation
- Peer review of build config
- Two-party build requirement
- Independent builder setup
- Separation of duties
- Build parameter controls
- Buildkit vs Tekton comparison
- Provenance signing keys
- Key rotation schedule
- Timestamp authority use
- Transparency log integration
- Monitoring for drift
- Incident response linkage
- Audit trail completeness
- Attestation schema breakdown
- Provenance vs attestation
- Signing key management
- Sigstore overview
- Cosign and Rekor integration
- Verification script templates
- Automated attestation checks
- Attestation storage model
- Versioning attestations
- Human-readable summaries
- Third-party validation paths
- Error handling in verification
- Auditor information needs
- Packaging SLSA evidence
- Timeline of attestations
- Chain of custody narrative
- Common auditor questions
- Gaps in Level 2 audits
- Remediation tracking system
- Evidence retention policy
- Cross-team coordination
- Review cycle timelines
- Stakeholder communication
- Feedback loop from auditors
- Identifying SLSA champions
- Standardizing build configs
- Templatized onboarding
- Metrics for compliance
- Peer audit process
- Escalation path design
- Conflict resolution models
- Documentation standards
- Change advisory boards
- Toolchain exception process
- Training delivery plan
- Feedback from developers
- Vendor attestation requirements
- Third-party SLSA levels
- Integration with procurement
- Risk scoring model
- Onboarding assessment
- Evidence exchange protocol
- Third-party toolchain audit
- Escalation process for gaps
- Contractual language
- Compliance tracking
- Remediation deadlines
- Termination triggers
- SLSA and SBOM overlap
- Timing of SBOM creation
- SBOM format standards
- Linking SBOM to provenance
- CycloneDX integration
- SPDX compatibility
- Vulnerability linkage
- Automated SBOM updates
- Human review process
- SBOM distribution controls
- Retention and access
- Customer disclosure policy
- Triggering SLSA review
- Attestation chain analysis
- Provenance timeline mapping
- Build environment snapshot
- Identifying compromised stages
- Scope of impact assessment
- Rollback decision framework
- Communication to stakeholders
- Regulatory reporting
- Post-mortem integration
- Process improvement tracking
- Lessons from real incidents
- Policy scope definition
- Applicability statements
- Exemption process
- Enforcement mechanisms
- Compliance measurement
- Audit readiness criteria
- Version control for policy
- Stakeholder review cycle
- Communication plan
- Training integration
- Review and update schedule
- Policy exception tracking
- Assessing current state
- Setting maturity targets
- Resource planning
- Tooling investment cases
- Milestone definition
- Success metrics
- Leadership communication
- Progress reporting
- Feedback integration
- Adjusting timelines
- Cross-org coordination
- Celebrating milestones
How this maps to your situation
- After a new security mandate requiring SLSA
- During third-party audit preparation
- When onboarding a high-risk vendor
- Before rolling out a new build system
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3 hours per week over 12 weeks, with on-demand access to all materials.
How this compares to the alternatives
Unlike generic security certifications or broad compliance courses, this program focuses specifically on SLSA implementation in real-world engineering environments, with templates and workflows tailored to practitioners influencing without authority.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.